CVE-2024-38572
Published: Jun 19, 2024
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix out-of-bound access of qmi_invoke_handler() Currently, there is no terminator entry for ath12k_qmi_msg_handlers hence facing below KASAN warning, ================================================================== BUG: KASAN: global-out-of-bounds in qmi_invoke_handler+0xa4/0x148 Read of size 8 at addr ffffffd00a6428d8 by task kworker/u8:2/1273 CPU: 0 PID: 1273 Comm: kworker/u8:2 Not tainted 5.4.213 #0 Workqueue: qmi_msg_handler qmi_data_ready_work Call trace: dump_backtrace+0x0/0x20c show_stack+0x14/0x1c dump_stack+0xe0/0x138 print_address_description.isra.5+0x30/0x330 __kasan_report+0x16c/0x1bc kasan_report+0xc/0x14 __asan_load8+0xa8/0xb0 qmi_invoke_handler+0xa4/0x148 qmi_handle_message+0x18c/0x1bc qmi_data_ready_work+0x4ec/0x528 process_one_work+0x2c0/0x440 worker_thread+0x324/0x4b8 kthread+0x210/0x228 ret_from_fork+0x10/0x18 The address belongs to the variable: ath12k_mac_mon_status_filter_default+0x4bd8/0xfffffffffffe2300 [ath12k] [...] ================================================================== Add a dummy terminator entry at the end to assist the qmi_invoke_handler() in traversing up to the terminator entry without accessing an out-of-boundary index. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < 95575de7dede7b1ed3b9718dab9dda97914ea775affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < b48d40f5840c505b7af700594aa8379eec28e925affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < a1abdb63628b04855a929850772de97435ed1555affected d889913205cf7ebda905b1e62c5867ed4e39f6c2 - < e1bdff48a1bb4a4ac660c19c55a820968c48b3f2 |
Linux | Linux | affected 6.3unaffected 0 - < 6.3unaffected 6.6.33 - <= 6.6.*unaffected 6.8.12 - <= 6.8.*unaffected 6.9.3 - <= 6.9.*+1 more versions |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now